Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41987
Total
3420
Critical
12405
High
12324
Medium
CVE ID Severity Score Description Published
CVE-2026-20275 HIGH 8.8 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … Sep 02, 2026
CVE-2026-20274 CRITICAL 9.8 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … Sep 02, 2026
CVE-2026-20212 CRITICAL 9.8 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This … Sep 02, 2026
CVE-2026-84838 HIGH 7.8 A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially … Sep 02, 2026
CVE-2026-84837 HIGH 7.8 A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by … Sep 02, 2026
CVE-2026-84677 MEDIUM 5.4 Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored … Sep 02, 2026
CVE-2026-84676 MEDIUM 4.3 Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by … Sep 02, 2026
CVE-2026-84675 HIGH 7.4 OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on … Sep 02, 2026
CVE-2026-84674 MEDIUM 5.4 Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in … Sep 02, 2026
CVE-2026-84673 HIGH 8.8 Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon … Sep 02, 2026
CVE-2026-84672 HIGH 8.8 Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display … Sep 02, 2026
CVE-2026-84671 HIGH 8.8 Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can … Sep 02, 2026
CVE-2026-84670 HIGH 8.8 Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory … Sep 02, 2026
CVE-2026-84669 HIGH 8.8 A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read … Sep 02, 2026
CVE-2026-84668 HIGH 8.8 Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled … Sep 02, 2026
CVE-2026-84667 HIGH 7.1 Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified … Sep 02, 2026
CVE-2026-84666 UNKNOWN Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage … Sep 02, 2026
CVE-2026-84665 HIGH 8.0 Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the … Sep 02, 2026
CVE-2026-84664 MEDIUM 5.4 Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL … Sep 02, 2026
CVE-2026-84663 MEDIUM 5.4 A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches. Sep 02, 2026
CVE-2026-84662 MEDIUM 4.3 Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL. Sep 02, 2026
CVE-2026-84661 MEDIUM 5.4 A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitForBuild` step when the `propagateAbort` parameter … Sep 02, 2026
CVE-2026-84660 MEDIUM 5.4 A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even … Sep 02, 2026
CVE-2026-84659 MEDIUM 4.3 Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox … Sep 02, 2026
CVE-2026-84658 MEDIUM 4.3 Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain … Sep 02, 2026